EP4295490A1 - Secure, efficient and reliable transmission of data in mission critical systems - Google Patents
Secure, efficient and reliable transmission of data in mission critical systemsInfo
- Publication number
- EP4295490A1 EP4295490A1 EP22764108.1A EP22764108A EP4295490A1 EP 4295490 A1 EP4295490 A1 EP 4295490A1 EP 22764108 A EP22764108 A EP 22764108A EP 4295490 A1 EP4295490 A1 EP 4295490A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- data
- priority
- transmission
- communications network
- high priority
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/90—Services for handling of emergency or hazardous situations, e.g. earthquake and tsunami warning systems [ETWS]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/12—Applying verification of the received information
- H04L63/126—Applying verification of the received information the source of the received data
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L47/00—Traffic control in data switching networks
- H04L47/50—Queue scheduling
- H04L47/62—Queue scheduling characterised by scheduling criteria
- H04L47/625—Queue scheduling characterised by scheduling criteria for service slots or service orders
- H04L47/6275—Queue scheduling characterised by scheduling criteria for service slots or service orders based on priority
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/12—Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/14—Session management
- H04L67/141—Setup of application sessions
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/50—Network services
- H04L67/60—Scheduling or organising the servicing of application requests, e.g. requests for application data transmissions using the analysis and optimisation of the required network resources
- H04L67/61—Scheduling or organising the servicing of application requests, e.g. requests for application data transmissions using the analysis and optimisation of the required network resources taking into account QoS or priority requirements
Definitions
- the present disclosure relates to computer networking, and more particularly, to an improved data transmissions technique for sending data in a mission critical system.
- FIG. 1A is a block diagram illustrating a data communications system for transmitting data from an internal server to an outside server using a unidirectional data communications network, according to one embodiment described herein.
- FIG. 1 B is a diagram illustrating a data communications system for transmitting data from an internal server to multiple outside servers using unidirectional data communications networks, according to one embodiment described herein.
- FIG. 2 is a block diagram illustrating a more detailed view of a data communications system shown in FIG. 1 , according to one embodiment described herein.
- FIG. 3 is a flow diagram illustrating a method for transmitting prioritized data over a unidirectional data communications network, according to one embodiment described herein.
- FIG. 4 is a diagram illustrating the transmission of keyframes containing data values of various priority levels from a mission critical system, according to one embodiment described herein.
- FIG. 5 is a block diagram illustrating a transmission of key frame fragments of a key frame with interspersed high priority data updates, according to one embodiment described herein.
- Embodiments described herein provide techniques for secure, efficient and reliable data transmission in mission critical systems.
- Data exchange is becoming common in even the most critical of systems.
- Historically critical systems have been isolated and designed to work with no need for data exchange with third party systems.
- critical systems are changing to react to the new demands of the connected world.
- Some of the connections are a result of centralized control (e.g., an oil field with multiple pump-and-rod installations miles apart communicating over Global System for Mobiles (GSM) modems) while others are related to the specific customer needs ⁇ e.g., sharing energy savings data or tracking weather data to determine if a data center should move virtual loads to another region to avoid a natural disaster).
- GSM Global System for Mobiles
- embodiments provide a secure, efficient and reliable means of transferring mission critical data in systems which transmit process-style data ⁇ e.g., tags, or points, coupled with alarms and other complex data structures).
- Embodiments can work with guaranteed delivery systems as well as telemetry based (non-guaranteed) delivery mechanisms.
- the data transmission is also unidirectional in nature (no acknowledgements of receipt are allowed according to the security policy and procedures typically in place in mission critical environments), providing a secure method of egressing data without allowing data ingress.
- Embodiments described herein can provide Quality of Service (QoS) functionality within the data stream by providing multiple priorities for various data types. Additionally, embodiments provide strong symmetric data encryption for the data stream, as well as index pages providing for fast data transmission by means of cached lookups. Emergent egress management is implemented in some embodiments, which selectively allows particular data values to bypass QoS functionality, e.g., in the case of emergencies.
- QoS Quality of Service
- Mission critical systems namely Supervisory Control and Data Acquisition (SCADA) systems and Programmable Logic Controllers (PLCs)
- SCADA Supervisory Control and Data Acquisition
- PLCs Programmable Logic Controllers
- tags or points
- alarms and other complex objects waveforms, manufacturing recipes, bills of materials, etc.
- OPC Open Platform Communications
- OPC-UA Open Platform Communications - United Architecture
- Embodiments described herein provide techniques for egressing mission critical data to non-mission critical applications.
- Embodiments employ an approach that is tolerant to missing data for low-priority elements, which is acceptable for non mission critical applications even though this would be unacceptable for internal mission critical communications.
- the transmission of data is unidirectional in nature. That is, data flows from the mission critical system to the non-mission critical system, but data cannot flow in the reverse direction (/.e., from the non-mission critical system to the mission critical system).
- Such a configuration helps to preserve the security of the mission critical system.
- FIG. 1A is a block diagram illustrating a data communications system for transmitting data from an internal server to an outside server using a unidirectional data communications network, according to one embodiment described herein.
- the system 100 includes an inside server within a mission critical environment that is configured to egress data to an outside server that is outside of the mission critical environment using a unidirectional gateway device.
- mission critical data is stream oriented. That is, the data is not finite, the data arrives and/or is collected in real time, and the expectation is that the data is transmitted as soon as possible. Additionally, mission critical data is typically ordered. In the event the data arrives out of order, the receiving non mission critical application is responsible for discarding the old/outdated packets.
- Mission critical data also has the capability of variable bit rates. In mission critical systems, constant bit rates are necessary for billing applications (e.g., for accurate consumption calculations), but variable bit rates are necessary for abnormal scenarios ⁇ e.g., peak avoidance, power system events and cyber security attack response).
- Real-time mission critical data systems are generally also capable of surviving connection loss, and generally are configured to remain current (/.e., a recent value is generally more desirable than an older packet that was dropped). Note that there are exceptions to this when dealing with transients or alarm conditions, and embodiments described herein can handle such exceptions using additional key frame techniques ⁇ e.g., sending alarm digests or performing an alarm interrogation).
- Mission critical data is also frequently compressed using a suitable data compression algorithm.
- a lossless compression algorithm ⁇ e.g., standard zip/gzip
- a lossless compression algorithm ⁇ e.g., standard zip/gzip
- systems receiving data from mission critical systems can tolerate missing packets in some circumstances, but the data received must be correct according to the system specifications.
- these receiving systems may be tolerant of missing packets to an extent, the receiving system must still have a mechanism for determining that a packet was missed. That is, the receiving system may employ a procedure to determine that a packet was lost, but the receiving system may not have a way to recover the lost data from the packet.
- the receiving system in such a scenario is generally unable to request retransmission of the data, as the data is being egressed from the mission critical system using a unidirectional network.
- Mission critical data is also generally encrypted.
- security is paramount and embodiments described herein use a symmetric algorithm with sufficient key length to ensure security.
- Mission critical systems generally have many levels and/or priorities and embodiments described herein can account for these levels and/or priorities when egressing data to non-critical systems. For instance, an alarm may have a priority of “high” while a real-time value for energy readings may be a priority of “normal”. For this reason, embodiments can implement the concept of QoS and priority within the stream.
- FIG. 1 B is a diagram illustrating a data communications system for transmitting data from an internal server to multiple outside servers using unidirectional data communications networks, according to one embodiment described herein.
- the diagram illustrates a system 120 that includes a mission critical system 130.
- the mission critical system 130 represents a computing environment where it is desirable for data to be able to flow out of the environment, but external data is not able to flow into the environment.
- the mission critical system 130 is configured to transmit data to multiple external locations 140(1)-(N) using multiple unidirectional data communications networks 135(1 )-(N).
- these unidirectional data communications networks 135(1 )-(N) can be of varying speeds.
- the unidirectional data communications network 135(1 ) has a speed of 5 Megabits per second (Mbps), while the unidirectional data communications network 135(N) has a speed of less than 5 Mbps.
- Mbps Megabits per second
- any unidirectional data communications network that allows data to flow out of, but not into, a computing environment can be used, consistent with the functionality described herein.
- a data priority management component for the mission critical system 130 could be configured to receive a plurality of data values to transmit to a remote system using unidirectional data communications networks.
- the data priority management component could prioritize the plurality of data values according to a plurality of priority levels.
- the data priority management component could then group the prioritized plurality of data values into one or more data updates for each of the plurality of priority levels.
- the data priority management component could enqueue the one or more data updates into a respective transmission queue corresponding to each of the plurality of priority levels, and could transmit the data updates over the unidirectional data communications network in an order determined based on the respective priority levels of the transmission queues.
- the data priority management component could utilize a transmission buffer configured to hold one or more data updates, and the data priority management component could fill the transmission buffer with data updates, giving preference to higher priority data updates first.
- the data priority management component could initially fill the transmission buffer using the data updates from the highest priority transmission queue, and could repeat this process for each lower priority transmission queue until the transmission buffer is full or until all transmission queues are empty. The data priority management component could then begin transmitting data from the beginning of the transmission buffer across the unidirectional data communications networks 135(1 )-(N).
- the data priority management component could generate one or more data updates corresponding to the new data values and could assign the generated data update(s) a priority value. For instance, the data priority management component could assign the priority value based on a data type of the new data values. As an example, the data priority management component could assign the generated data update(s) a high priority value if the new data values are alarms and/or critical instantaneous data readings. As another example, the data priority management component could assign the generated data update(s) a low priority value if the new data values are energy and consumption metrics.
- the data priority management component could assign the generated data update(s) a low priority value if the new data values are energy and consumption metrics.
- the data priority management component could then insert the newly generated data update(s) into the transmission buffer, at a position corresponding to the priority level assigned to the generated data update(s). For example, if the data update(s) are assigned a high priority level, the data priority management component could insert the data update(s) into the transmission buffer at a position ahead of all data update(s) having a lower priority level. Doing so ensures that high priority data is transmitted to the external system more quickly. This is particularly true in embodiments where the amount of data being generated by the mission critical system 130 exceeds the network bandwidth of the unidirectional network.
- the unidirectional data communications network 135(N) would not be able to transmit these data values in real-time due to the network having a bandwidth of less than 5 Mbps.
- embodiments can ensure the highest priority data values are transmitted ahead of lower priority data values, thereby improving the performance of the system and especially in systems with limited unidirectional network throughput.
- the data priority management component can further be configured to periodically transmit a key frame to one or more external systems over the unidirectional data communications networks.
- the key frame represents a snapshot of monitored data values at the mission critical system 130 at a given moment in time.
- the mission critical system could be configured to monitor a plurality of data metrics of various priority levels, and the key frame can include a data value for each of the plurality of data metrics at a given timestamp.
- Such a key frame can be divided into a plurality of key frame fragments, representing portions of the key frame and each containing one or more data values from the snapshot of data values.
- the data priority management component can be configured to priority the transmission of data updates having a priority level greater than a predefined threshold level of priority.
- the data priority management component could be configured to prioritize high priority data updates over key frame fragments.
- the data priority management component could pause transmitting the key frame fragments and could begin transmitting the one or more high priority data updates over the unidirectional networks. Once all high priority data updates have been transmitted, the data priority management component could resume transmitting the key frame fragments. In doing so, the data priority management component ensures that the most important (i.e., updates having the highest priority level) are transmitted as quickly as possible, while still ensuring that snapshots of all data values (i.e., key frames) are periodically transmitted to the external system.
- FIG. 2 is a block diagram illustrating a more detailed view of a data communications system shown in FIG. 1 , according to one embodiment described herein.
- the system 200 includes a data transmission system 210, a unidirectional data communications network 250 and a data receiver system(s) 260.
- the unidirectional data communications network 250 represents any suitable unidirectional data communications network, with examples including (without limitation) a unidirectional local area network (LAN), a wide area network (WAN), a unidirectional wireless network, and so on.
- LAN local area network
- WAN wide area network
- wireless network unidirectional wireless network
- the data transmission system 210 includes one or more computer processors 212, a memory 215, an input module(s) 220, and a network interface controller 240.
- the data transmission system 210 can also include one or more input modules (not shown) that represent devices that provide inputs to the data transmission system 210. Such inputs may be provided, for example, in the form of digital inputs or analog signals.
- the input module can include circuitry for converting the analog signals into logic signals that can be processed by the processor 212.
- the memory 215 contains a data transmission component 220 and an operating system 235.
- the data transmission component 220 includes a priority management component 225 and a queue management component 230.
- the priority management component 225 is configured to assign priority levels to data values collected by the data transmission system 210 (e.g., data values received from the one or more input devices).
- the priority management component 225 can assign the priority levels based on a variety of different criteria including, without limitation, a data type of the data values, an input device from which a data value was collected, a data value exceeding a predefined threshold level, and so on. More generally, any suitable prioritization technique can be used, consistent with the functionality described herein.
- the prioritized data values can then be grouped into data updates and the queue management component 230 can place the data updates into a respective transmission queue according to the corresponding priority level.
- the queue management component 230 can then transmit data updates from the transmission queues in an order according to the priority levels corresponding to the transmission queues using the unidirectional network 250, e.g., data updates in higher priority transmission queues can be transmitted before data updates in lower priority transmission queues.
- the data receiver system 260 includes a processor 262, a memory 265 and a network interface controller 270.
- the memory 265 includes a data receiver component 266 and an operating system.
- the data receiver component 266 can receive the key frames from the data transmission component 220 over the unidirectional network 250, and can process the received key frames to extract the data from the key frames and process the data in an application-specific manner. For instance, the data receiver component 266 could generate a graphical user interface (GUI) illustrating a graphical representation of the received data.
- GUI graphical user interface
- the data receiver component 266 could generate a graphical representation illustrating the received temperature value and color-coded depending on a predefined range the temperature is in (e.g., the temperature value could be displayed in green when it is in an acceptable range and red if the temperature value exceeds the acceptable range). More generally, numerous different ways for processing the received data exist and the data receiver component 266 can be configured to handle the received data in any suitable fashion, consistent with the functionality described herein.
- this configuration is done out of band in that this information is pre-shared and it is not transferred across the communication medium.
- the configuration is transmitted dynamically from the transmitter to the receiver using any suitable format for describing the data transmittal configuration.
- the configuration acts as a contract and the transmitter and receiver are configured to abide by the contract.
- the configuration can also include the classifications of the data.
- the data can be tagged with a priority value so that it is handled properly by the transmitter and receiver.
- Some data is more tolerant of packet loss during transmission ⁇ e.g., real time data), whereas the transmission of other data may, in practice, need a guaranteed delivery ⁇ e.g., alarms).
- the configuration defining attributes of the data transfer process can account for these
- a data transmission component on a data transmitter system first reads the configuration to take inventory of the data that it is responsible for sending. The data transmission component could then provision the data according to the priority specified in the configuration. The data transmission component could also define a transmit queue for each priority and data updates are generated with current data for each queue. The data transmission component could start a timer for each priority level (using the interval specified by the configuration) and could generate and transmit a data update each time the timer elapses. Additional logic may be employed to make data updates more frequent when abnormal events occur or other events take place.
- the data transmission component monitors the system for data changes and sends off a packet of changes as frequently as allowed by the configuration (a “sleep interval” is defined that throttles updates).
- a race condition occurs in that a key frame may be in progress when a data change update is sent.
- the data transmission component can timestamp each data change update so that the receiver selects the most recent data when processing key frames.
- a specific priority can be placed for emergency situations. The data transmission component could move data marked with this priority to the front of the queue to be transmitted immediately.
- a key frame can be shown as a table that includes one row for each data component to be transferred. For example:
- Example 1 the columns are as follows:
- updates are sent in between key frames when data changes occur (throttled by configuration).
- Data updates can be visualized as a table that contains one record for every data update. For example:
- Example 2 the columns are as follows:
- the data transmission component employs a process comprising, for each packet of data (key frames and data updates) that is received:
- the receiver contains computer logic that allows discrimination of the data depending on the priority and the packet type.
- the data receiver component can first determine if the packet is a key frame or a data update packet. If the packet is determined to be a key frame, the data receiver component can place the packet in a holding area waiting to be processed. In one embodiment, only one key frame is retained; in the unlikely event that multiple key frames begin to stack up as a result in delayed processing, only the most recent key frame is retained. In a particular embodiment, the exception to this rule is for alarms (e.g., where all data updates and key frame fragments are guaranteed to be processed).
- the data receiver component can then process data updates and key frame fragments in the order of their priority. Key frames may contain necessary information to process upcoming updates.
- the data receiver component can cache the index and tag names of each record in the data update and key frame fragment, thereby allowing for a smaller update packet (as tag names can get very long).
- the data receiver component can compare the transmit timestamp with any cached data timestamps to ensure that only the most recent data is retained.
- the data receiver component is configured to process update records one record at a time.
- the data receiver component can use the index value to lookup the tag name (provided by a previous data update or key frame fragment).
- the data receiver component can compare the transmit timestamp to cached data (provided by a previous update or key frame) to ensure that only the most recent data is retained.
- update records are also subject to be discarded if the receive buffer is full.
- data update packets can be marked for emergency egress. Packets with this designation will bypass all queues, are not subject to removal and will be processed immediately.
- a common use case for this concept is for data egress in mission critical systems.
- mission critical systems the systems and techniques described herein can be applied in a variety of different contexts and the examples involving mission critical systems are provided for illustrative purposes and without limitation.
- this may be done with a unidirectional gateway, but could also be achieved with a layer 2/3 firewall or other appropriate device.
- a college campus may have invested heavily in an energy savings initiative and would like to show their student body the campus energy consumption on a kiosk in the student union building.
- the unidirectional gateway would sit between the secure (power systems) network and the less-secure (student/public) network.
- the data transmission approach presented herein could ensure that the kiosk receives frequent and reliable updates.
- Another common use case involves distributed systems where many field devices collect data. This data transmission approach could be used to federate this data to a centralized location over unreliable transmission mediums such as GSM.
- GSM unreliable transmission mediums
- An example is an oil field with many devices spread across multiple miles communicating over the cellular network.
- these systems suffer a multitude of errors as a result of the disconnectedness of the communications.
- these systems generally use legacy protocols that have no element of security.
- Embodiments described herein provide a secure, reliable connection (over a generally non-reliable medium) due to the self-healing nature of this design.
- FIG. 3 illustrates a method for transmitting data (e.g., data from a mission critical system to a non-critical system) over a unidirectional network, according to one embodiment described herein.
- the method 300 begins at block 310, where the data transmission component 220 receives a plurality of data values to transmit to a remote system using a unidirectional data communications network.
- the data transmission component 220 prioritizes the plurality of data values according to a plurality of priority levels (block 315).
- the data transmission component 220 groups the prioritized plurality of data values into one or more data updates for each of the plurality of priority levels (block 320). Additionally, the data transmission component 220 enqueues the one or more data updates into a respective transmission queue corresponding to each of the plurality of priority levels (block 325). In the depicted embodiment, the data transmission component 220 transmits the data updates over the unidirectional data communications network in an order determined based on the respective priority levels of the transmission queues (block 330).
- the data transmission component 220 transmits a key frame containing a snapshot of monitored data values at a given point in time, where the key frame comprises a plurality of key frame fragments and where transmission at least one data update is interspersed between transmission of two or more of the plurality of key frame fragments, based on a priority level associated with the at least one data update (block 335), and the method 300 ends.
- FIG. 4 is a diagram illustrating the transmission of keyframes containing data values of various priority levels from a mission critical system, according to one embodiment described herein.
- the diagram 400 includes a plurality of key frames of various priority levels.
- the data priority management component is configured to assign three different priority levels to data values, where alarms and critical instantaneous readings 410 are assigned the highest priority level, non-critical instantaneous readings 415 are assigned a medium priority level and energies and consumption metrics 420 are assigned the lowest priority levels.
- the data priority management component has transmitted three key frames over the window of time.
- a key frame can refer to a full snapshot of the data of the mission critical system.
- numerous data value updates for alarms and critical instantaneous readings 410 having the highest priority level were interspersed during the transmission of the key frame 425.
- the key frame data as well as the data value updates can be associated with timestamp values, and the receiving system can be configured to discard any later received values having a timestamp that predates an earlier received value.
- FIG. 5 is a block diagram illustrating a transmission of key frame fragments of a key frame with interspersed high priority data updates, according to one embodiment described herein.
- the diagram 500 illustrates the transmission of key frame fragments 510(1)-(N) of a key frame of data from a mission critical system.
- the key frame can include a full snapshot of the data on the mission critical system at a particular point in time. Such a snapshot can include a plurality of data values monitored on the mission critical system, ranging from the lowest priority data values to the highest priority data values.
- a number of the transmission of the key frame fragments 510(1)-(N) are interspersed with the transmission of a number of high priority updates 520(1 )-(N).
- the priority management component 225 can be configured to prioritize the transmission of data updates based on respective priority levels and can transmit higher priority updates even during the transmission of a key frame.
- the receiving system can be configured to compare timestamps associated with the values and to use the value with the most recent timestamp (e.g., discarding the value(s) with older timestamps). Doing so enables higher priority updates to reach the external system more quickly, which is particularly advantageous on unidirectional networks with limited bandwidth.
- aspects disclosed herein may be implemented as a system, method or computer program product. Accordingly, aspects may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, micro-code, etc.) or an embodiment combining software and hardware aspects that may all generally be referred to herein as a “circuit,” “module” or “system.” Furthermore, aspects may take the form of a computer program product embodied in one or more computer-readable medium(s) having computer- readable program code embodied thereon.
- the computer-readable medium may be a non-transitory computer-readable medium.
- a non-transitory computer-readable medium may be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing.
- non-transitory computer-readable medium can include the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
- Program code embodied on a computer-readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
- Computer program code for carrying out operations for aspects of the present disclosure may be written in any combination of one or more programming languages. Moreover, such computer program code can execute using a single computer system or by multiple computer systems communicating with one another (e.g., using a local area network (LAN), wide area network (WAN), the Internet, etc.). While various features in the preceding are described with reference to flowchart illustrations and/or block diagrams, a person of ordinary skill in the art will understand that each block of the flowchart illustrations and/or block diagrams, as well as combinations of blocks in the flowchart illustrations and/or block diagrams, can be implemented by computer logic ⁇ e.g., computer program instructions, hardware logic, a combination of the two, etc.).
- computer program instructions may be provided to a processor(s) of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus. Moreover, the execution of such computer program instructions using the processor(s) produces a machine that can carry out a function(s) or act(s) specified in the flowchart and/or block diagram block or blocks.
- each block in the flowchart or block diagrams may represent a module, segment or portion of code, which comprises one or more executable instructions for implementing the specified logical function(s).
- the functions noted in the block may occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved.
- aspects disclosed herein may be implemented as a system, method or computer program product. Accordingly, aspects may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, micro-code, etc.) or an embodiment combining software and hardware aspects that may all generally be referred to herein as a “circuit,” “module” or “system.” Furthermore, aspects may take the form of a computer program product embodied in one or more computer-readable medium(s) having computer- readable program code embodied thereon.
- the computer-readable medium may be a non-transitory computer-readable medium.
- a non-transitory computer-readable medium may be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing.
- non-transitory computer-readable medium can include the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
- Program code embodied on a computer-readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
- Computer program code for carrying out operations for aspects of the present disclosure may be written in any combination of one or more programming languages. Moreover, such computer program code can execute using a single computer system or by multiple computer systems communicating with one another (e.g., using a local area network (LAN), wide area network (WAN), the Internet, etc.). While various features in the preceding are described with reference to flowchart illustrations and/or block diagrams, a person of ordinary skill in the art will understand that each block of the flowchart illustrations and/or block diagrams, as well as combinations of blocks in the flowchart illustrations and/or block diagrams, can be implemented by computer logic ⁇ e.g., computer program instructions, hardware logic, a combination of the two, etc.).
- computer program instructions may be provided to a processor(s) of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus. Moreover, the execution of such computer program instructions using the processor(s) produces a machine that can carry out a function(s) or act(s) specified in the flowchart and/or block diagram block or blocks.
- each block in the flowchart or block diagrams may represent a module, segment or portion of code, which comprises one or more executable instructions for implementing the specified logical function(s).
- the functions noted in the block may occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved.
Landscapes
- Engineering & Computer Science (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- Health & Medical Sciences (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Medical Informatics (AREA)
- General Health & Medical Sciences (AREA)
- Business, Economics & Management (AREA)
- Emergency Management (AREA)
- Environmental & Geological Engineering (AREA)
- Public Health (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US202163157269P | 2021-03-05 | 2021-03-05 | |
| PCT/US2022/018840 WO2022187576A1 (en) | 2021-03-05 | 2022-03-04 | Secure, efficient and reliable transmission of data in mission critical systems |
Publications (3)
| Publication Number | Publication Date |
|---|---|
| EP4295490A1 true EP4295490A1 (en) | 2023-12-27 |
| EP4295490A4 EP4295490A4 (en) | 2025-01-29 |
| EP4295490B1 EP4295490B1 (en) | 2026-05-06 |
Family
ID=83154590
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP22764108.1A Active EP4295490B1 (en) | 2021-03-05 | 2022-03-04 | Secure, efficient and reliable transmission of data in mission critical systems |
Country Status (4)
| Country | Link |
|---|---|
| US (2) | US12445457B2 (en) |
| EP (1) | EP4295490B1 (en) |
| CN (1) | CN117157886A (en) |
| WO (1) | WO2022187576A1 (en) |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN118193214B (en) * | 2024-03-29 | 2024-12-20 | 郭明娟 | Big data management system and method based on distributed architecture |
| CN120940602B (en) * | 2025-07-28 | 2026-02-24 | 常州同泰高导新材料有限公司 | A temperature monitoring and communication control system, method and apparatus for continuous casting of copper rods. |
Family Cites Families (11)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6125398A (en) | 1993-11-24 | 2000-09-26 | Intel Corporation | Communications subsystem for computer-based conferencing system using both ISDN B channels for transmission |
| JP2007013998A (en) * | 2006-07-20 | 2007-01-18 | Hitachi Electronics Service Co Ltd | Network system |
| US8139581B1 (en) | 2007-04-19 | 2012-03-20 | Owl Computing Technologies, Inc. | Concurrent data transfer involving two or more transport layer protocols over a single one-way data link |
| US8396963B2 (en) * | 2010-09-29 | 2013-03-12 | Schneider Electric USA, Inc. | Networked devices for monitoring utility usage and methods of using the same |
| US9509771B2 (en) * | 2014-01-14 | 2016-11-29 | International Business Machines Corporation | Prioritizing storage array management commands |
| CN104836745B (en) | 2015-05-08 | 2017-12-12 | 中国人民解放军61600部队 | A kind of Internet tunneling approach based on unidirectional transmission equipment |
| US10536345B2 (en) * | 2016-12-28 | 2020-01-14 | Google Llc | Auto-prioritization of device traffic across local network |
| US10739761B2 (en) * | 2017-11-16 | 2020-08-11 | Intel Corporation | Scalable edge compute in a distributed control environment |
| US10868864B2 (en) * | 2018-04-16 | 2020-12-15 | Hewlett Packard Enterprise Development Lp | System and method for fault-tolerant remote direct memory access using single port host channel adapter hardware |
| CN108880634B (en) * | 2018-06-12 | 2021-03-02 | 珠海云洲智能科技股份有限公司 | Communication method |
| US11917514B2 (en) | 2018-08-14 | 2024-02-27 | Rapidsos, Inc. | Systems and methods for intelligently managing multimedia for emergency response |
-
2022
- 2022-03-04 US US18/280,309 patent/US12445457B2/en active Active
- 2022-03-04 WO PCT/US2022/018840 patent/WO2022187576A1/en not_active Ceased
- 2022-03-04 EP EP22764108.1A patent/EP4295490B1/en active Active
- 2022-03-04 CN CN202280028392.5A patent/CN117157886A/en active Pending
-
2025
- 2025-09-09 US US19/323,020 patent/US20260012463A1/en active Pending
Also Published As
| Publication number | Publication date |
|---|---|
| EP4295490B1 (en) | 2026-05-06 |
| WO2022187576A1 (en) | 2022-09-09 |
| US20260012463A1 (en) | 2026-01-08 |
| CN117157886A (en) | 2023-12-01 |
| EP4295490A4 (en) | 2025-01-29 |
| US12445457B2 (en) | 2025-10-14 |
| US20240372875A1 (en) | 2024-11-07 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US20260012463A1 (en) | Secure, efficient and reliable transmission of data in mission critical systems | |
| EP2890065B1 (en) | Systems and methods for managing congestion | |
| EP4024778B1 (en) | Method for determining required bandwidth for data stream transmission, and devices and system | |
| US10594617B2 (en) | Probabilistic normalized congestion indication based on packet size | |
| US11095568B2 (en) | Systems and methods for network scheduling and re-transmission buffering | |
| EP3120253B1 (en) | Flow aware buffer management for data center switches | |
| CN111835708B (en) | Feature information analysis method and device | |
| EP2266262B1 (en) | System and method for application layer resource traffic control | |
| CN118474039A (en) | A TSN network medium system for precise flow control | |
| US20140164640A1 (en) | Small packet priority congestion control for data center traffic | |
| EP2979407A1 (en) | Re-marking of packets for queue control | |
| CN120151815A (en) | An adaptive packet data transmission system and method based on Beidou short message | |
| WO2017045501A1 (en) | Packet scheduling method and apparatus, and storage medium | |
| CN111372284B (en) | Congestion processing method and device | |
| CN117278484A (en) | Flow control method, device, equipment and storage medium based on token bucket algorithm | |
| EP2709320B1 (en) | Method and apparatus for sending packet | |
| CN101826981B (en) | Method for processing event message, northbound interface and operation support system | |
| US7792036B2 (en) | Event processing in rate limited network devices | |
| CN113904994B (en) | A method for unified reporting platform of home gateway big data | |
| CN103200112A (en) | Computer network transmission control protocol (TCP) flow control method | |
| US20180227271A1 (en) | Method for transmitting information between two domains with distinct security levels | |
| WO2021012291A1 (en) | Device and method for exporting telemetry data | |
| Irawan et al. | Performance evaluation of queue algorithms for video-on-demand application | |
| US9306854B2 (en) | Method and apparatus for diagnosing interface oversubscription and microbursts | |
| Baniamerian et al. | NCE: An ECN dual mechanism to mitigate micro-bursts |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20230920 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| A4 | Supplementary search report drawn up and despatched |
Effective date: 20250107 |
|
| RIC1 | Information provided on ipc code assigned before grant |
Ipc: H04L 67/12 20220101ALI20241220BHEP Ipc: H04L 67/61 20220101ALI20241220BHEP Ipc: H04L 67/141 20220101ALI20241220BHEP Ipc: H04B 1/52 20150101AFI20241220BHEP |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: GRANT OF PATENT IS INTENDED |
|
| RIC1 | Information provided on ipc code assigned before grant |
Ipc: H04B 1/52 20150101AFI20251127BHEP Ipc: H04L 67/141 20220101ALI20251127BHEP Ipc: H04L 67/61 20220101ALI20251127BHEP Ipc: H04L 67/12 20220101ALI20251127BHEP |
|
| INTG | Intention to grant announced |
Effective date: 20251208 |
|
| GRAS | Grant fee paid |
Free format text: ORIGINAL CODE: EPIDOSNIGR3 |
|
| GRAA | (expected) grant |
Free format text: ORIGINAL CODE: 0009210 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE PATENT HAS BEEN GRANTED |
|
| AK | Designated contracting states |
Kind code of ref document: B1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| REG | Reference to a national code |
Ref country code: CH Ref legal event code: F10 Free format text: ST27 STATUS EVENT CODE: U-0-0-F10-F00 (AS PROVIDED BY THE NATIONAL OFFICE) Effective date: 20260506 Ref country code: GB Ref legal event code: FG4D |